Two ways to use this beyond the catalogue: run the checks yourself, or read what we already know.
A single binary you put into your pipeline. It reads your files on your machine, checks which MCP servers your project connects, and fails the build when something is not allowed.
Nothing but package names ever leaves your machine — and only if you give it a key. Read it at /docs/agent/
Ask us what we know about a package: today's verdict, what our rules found, and whether a recent release started doing something it did not do before.
The same data the agent uses, for your own tools. Read it at /docs/api/